# BlackCat

> As of 2026-07-26, BlackCat is a threat actor tracked by Threadlinqs Intelligence across 6 threats spanning ransomware, threat actor, threat intel. Also known as ALPHV, ALPHV Ransomware Affiliates. ATT&CK coverage spans 91 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), T1657 (Financial Theft).

- **Tracked threats:** 6
- **Categories:** RANSOMWARE, THREAT_ACTOR, THREAT_INTEL
- **Also known as:** ALPHV, ALPHV Ransomware Affiliates
- **As of:** 2026-07-26

## ATT&CK techniques observed

91 techniques observed across 6 of 6 tracked threats. Tactics: Discovery (18), Credential Access (8), Impact (8), Stealth (formerly Defense Evasion) (8), Collection (7), Defense Impairment (6).

- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 6 of 6 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 6 of 6 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 5 of 6 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 6 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 4 of 6 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 4 of 6 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 6 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 3 of 6 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 3 of 6 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 3 of 6 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 3 of 6 tracked threats

## Tracked threats

- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — HIGH
- [Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months](https://intel.threadlinqs.com/threat/TL-2026-1294) — HIGH
- [Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims](https://intel.threadlinqs.com/threat/TL-2026-1264) — MEDIUM
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme](https://intel.threadlinqs.com/threat/TL-2026-1166) — MEDIUM
- [DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy](https://intel.threadlinqs.com/threat/TL-2026-1155) — HIGH
- [Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)](https://intel.threadlinqs.com/threat/TL-2026-0810) — HIGH

## Related CVEs

7 CVEs referenced by tracked BlackCat activity.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/BlackCat
